March 15, 2022 · Applied Cybernetics Group
CVE-2019-1069 — Microsoft Task Scheduler
known ransomware use
Microsoft Task Scheduler Privilege Escalation Vulnerability
- Added to KEV
2022-03-15- Federal due date
2022-04-05- Vendor
- Microsoft
- Product
- Task Scheduler
- EPSS
- 93.1th percentile (score 0.061, as of
2026-09-16) - NVD CVSS v3.1
- 7.8 (HIGH)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-1069
CISA short description
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
Required action
Apply updates per vendor instructions.
NVD description
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.